Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It does occur to me that if this did system-call redirection and banned the unlink (and maybe rename?) syscalls from working in it's executed commands, you could get a fair degree of safety.


Is it possible to do system call redirection??


I don't know of a way to redirect syscalls, but they can be limited.

https://www.kernel.org/doc/Documentation/prctl/seccomp_filte...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: